114
Figure 49
PAT operation
See
for an example. Packets 1 and 2 with different source ports are from Host A, and Packets
3 with the same source port as packet 1 is from Host B. PAT maps the source IP addresses of the three
packets to the same NAT address and uses different port numbers to make each unique. When the NAT
device receives a response packet, it translates the destination address and port number of the packet,
and forwards it to the target host.
PAT supports the following mapping behaviors:
•
Endpoint-Independent Mapping
—Uses the same IP and port mapping for packets from the same
source address and port to any destination IP and port. An EIM entry is generated to record the IP
and port mapping. This behavior allows packets from any external host to access the internal user
by using the NAT address and port, which improves communication among hosts that connect to
different NAT gateways.
•
Address and Port-Dependent Mapping
—Uses different IP and port mappings for packets from the
same source IP and port to different destination IP addresses and ports. This behavior does not
allow packets from an external host to any NAT address and port unless the internal host has
previously sent a packet of the same protocol to that external host. This behavior is secure, but it is
inconvenient for internal hosts connecting to different NAT gateways to access each other by using
the NATed external addresses.
NAT Server
The NAT Server feature maps a NAT address and port number to the real IP address and port number of
an internal server. This feature allows servers in the private network to provide services to external users.
shows how NAT Server works.
Содержание MSR 2600 Series
Страница 6: ...We appreciate your comments...
Страница 33: ...18 AC vlan1 quit...
Страница 113: ...98 Figure 41 Creating a record d On the page that appears select IPv6 Host AAAA as the resource record type...
Страница 118: ...103...
Страница 168: ...153 H323 Enabled ICMP ERROR Enabled...
Страница 170: ...155 Task Command Display FIB entries display fib vpn instance vpn instance name ip address mask mask length...